Certification
Major and minor nonconformities, and the six-month clock behind one of them
The grade an auditor puts on a finding decides what happens to your certificate, and the definition separating the two is narrower and more useful than most summaries suggest. It is not about how serious the problem feels. It is about one specific question.
Facts checked — 2026-09-11
How the two grades differ
| Minor | Major | |
|---|---|---|
| Definition | A nonconformity that does not affect the capability of the management system to achieve its intended results. | A nonconformity that does affect that capability. |
| Typical shape | A single lapse — one access review missed, one record not retained. | A required process absent altogether, a systemic failure, or significant doubt that effective control is in place. |
| Effect | Corrective action plan and evidence, within a defined window. Certification proceeds. | Blocks the certification recommendation until corrected and verified. |
| The clock | Set by your certification body. | If closure cannot be verified within six months of the last day of Stage 2, another Stage 2 is required. |
Definitions and the six-month rule are from ISO/IEC 17021-1:2015 (clauses 3.12, 3.13 and 9.5.3.2), the standard certification bodies are accredited against. Paraphrased; it is copyrighted.
The question that decides the grade
A major nonconformity is one that affects the capability of the management system to achieve its intended results. A minor is one that does not. That is the whole distinction, and it is more precise than the informal version people carry around — that majors are big problems and minors are small ones.
The difference matters because it explains gradings that otherwise look inconsistent. A single missed access review is a minor even though unauthorised access is a serious risk, because one lapse does not mean the system cannot work. An internal audit programme that was never run is a major even though nothing has gone wrong yet, because without it the management system has no mechanism to find its own failures. Severity of the underlying risk is not the test; capability of the system is.
ISO/IEC 17021-1 also gives auditors grounds to classify something as major where there is significant doubt that effective process control is in place, or that outputs will meet requirements. That is a judgement, and it is one accreditation exists to keep honest.
Several minors can become a major
This is the provision most worth knowing in advance, because it changes how you should react to a list of small findings.
A number of minor nonconformities against the same requirement or issue can demonstrate a systemic failure, and on that basis be raised as a major. Four separate records missing from four different months is not really four independent lapses — it is evidence that the process for producing that record does not reliably run.
So the instinct to fix each minor in isolation and move on is the wrong one. When several findings cluster on one requirement, the useful response is to treat them as one problem with a common cause and say so, because an auditor looking at the same cluster is asking whether it is systemic. Arriving with that analysis already done is considerably better than having it proposed to you.
The six-month clock
Here is the consequence of a major that is rarely spelled out. If the certification body cannot verify that corrections and corrective actions for a major nonconformity have been implemented within six months after the last day of Stage 2, it must conduct another Stage 2 audit before it can recommend certification.
Not another look at the finding — another Stage 2. The full second-stage audit again, with its fees and its scheduling, because too much time has passed for the original evidence to still describe the system.
In practice six months is generous for most majors and tight for the ones that require a process to run before it can be evidenced. If your major is "no internal audit programme", closing it means actually conducting an internal audit, acting on what it finds, and holding a management review — a sequence with real elapsed time in it. Start that immediately rather than after the report arrives.
At recertification the timing works differently and is stricter in one respect: time limits for correcting a major are defined and must be completed before the existing certification expires. The clock is your certificate’s expiry date rather than a six-month window.
Which findings actually become majors
Almost never the technical controls. Auditors find misconfigured things, incomplete asset inventories and patching gaps constantly, and those are usually minors — they are lapses within a system that is otherwise working.
The majors cluster in the mandatory clauses, and the same three come up repeatedly: no internal audit performed, no management review held, and a risk assessment that exists as a document but was never actually run as a process. Each one removes a mechanism the management system needs in order to function, which is exactly what the definition of a major describes.
The pattern is worth internalising because it inverts where most teams put their preparation effort. The technical work feels like the real work and produces minors. The governance work feels like paperwork and is where the certificate-blocking findings live.
What closing one actually requires
Every nonconformity needs two things that are easy to conflate: the fix, and the reason it happened. Repairing the instance without addressing the cause is the most common reason a closure is rejected and a finding reappears at the next audit — which is the point at which a recurring minor starts looking systemic.
Practically: correct the specific instance, work out why the process allowed it, change the process, and keep evidence of all three with dates. An auditor verifying closure is checking whether the system now prevents recurrence, not only whether the symptom is gone.
And treat the dates as part of the evidence. Closure verification is about what happened and when, so a corrective action with no record of when it was implemented is difficult to accept however genuinely it was done.
Common questions
What is the difference between a major and minor nonconformity?
A major nonconformity affects the capability of the management system to achieve its intended results; a minor does not. The test is the effect on the system’s capability, not the severity of the underlying risk — which is why one missed access review is usually a minor and an internal audit programme that never ran is a major.
Can several minor nonconformities become a major?
Yes. A number of minors against the same requirement or issue can demonstrate a systemic failure and be classified as a major on that basis. When findings cluster on one requirement, treat them as one problem with a common cause rather than as separate fixes.
How long do we have to close a major nonconformity?
If the certification body cannot verify that corrections and corrective actions have been implemented within six months after the last day of Stage 2, it must conduct another Stage 2 audit before recommending certification. At recertification, the limit is instead that closure must be completed before the existing certification expires.
Does a minor nonconformity stop us being certified?
No. You submit a corrective action plan and evidence within the window your certification body sets, and certification proceeds. Minors are an ordinary outcome of a real audit — a report with none at all is less common than teams expect.
What are the most common major nonconformities?
No internal audit performed, no management review held, and a risk assessment that exists as a document but was never run as a process. They cluster in the mandatory clauses rather than the technical controls, because each removes a mechanism the management system needs to function.
Why was our corrective action rejected?
Usually because it fixed the instance without addressing the cause. Closure verification asks whether the system now prevents recurrence, so it needs the correction, the analysis of why the process allowed it, the change to the process, and dated evidence of all three.
The bottom line
Grade is about the system’s capability, not the size of the risk — which is why the governance clauses produce the certificate-blocking findings and the technical controls mostly produce minors. If you do collect a major, start closing it the day you hear about it: six months sounds long until closure requires a process to actually run.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
ISO 22301 — Business Continuity Management
Know which activities cannot stop, how long they can be down, and what you will actually do — tested before you need it.
Related insights
Certification
The Statement of Applicability, and why an auditor opens it first
The document that shows whether your management system has reasoning behind it — and the one most organisations build backwards.
Certification
Stage 1 and Stage 2: what each audit tests, and why Stage 1 is not a rehearsal
One checks that you are ready to be audited. The other is the audit. Both feed the certification decision.
Certification
ISO 27001:2013 certificates have expired — including the ones with later dates on them
The window closed on 31 October 2025. A lapsed holder is treated as a new client — which is the part most summaries leave out.